← Back

Snowplow

snowplow

6 CVEs • 4 products

Products (4)

Click to collapse
Toggle
Iglu Server
iglu_server
Enrich
enrich
Snowbridge
snowbridge

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Snowplow
1Stream Collector
Apr 15, 2025
Apr 3, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establishes payload limits). It involves sending very large payloads to the Collector and can render it unres...Show more
This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establishes payload limits). It involves sending very large payloads to the Collector and can render it unresponsive to the rest of the requests. As a result, data would not enter the pipeline and would be potentially lost.Show less
1Snowplow
1Iglu Server
Apr 8, 2025
Apr 3, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated endpoint. It can render Iglu Server completely unresponsive. If the operation of Iglu Server is not...Show more
An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated endpoint. It can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.Show less
1Snowplow
1Snowbridge
Apr 23, 2025
Apr 3, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It involves attaching an invalid GTM SS preview header to events, causing them to be retried indefinitely. As a result, the per...Show more
An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It involves attaching an invalid GTM SS preview header to events, causing them to be retried indefinitely. As a result, the performance of forwarding events to GTM SS overall can be affected (latency, throughput).Show less
1Snowplow
1Iglu Server
Apr 10, 2025
Apr 3, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47212, but involves a different kind of malicious payload. As above, it can render Iglu Server completely unresponsive. If the operation...Show more
An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47212, but involves a different kind of malicious payload. As above, it can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.Show less
1Snowplow
1Enrich
Apr 23, 2025
Apr 3, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to the pipeline. Upon receiving this event and trying to validate it, Enrich crashes and attempts to rest...Show more
An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to the pipeline. Upon receiving this event and trying to validate it, Enrich crashes and attempts to restart indefinitely. As a result, event processing would be halted.Show less
1Snowplow
1Iglu Server
Apr 8, 2025
Apr 3, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu Server and can render it completely unresponsive. If the operation of Iglu Server is n...Show more
An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu Server and can render it completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.Show less